No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2750622 - PeerSpot reviewer
Technical Lead at a tech vendor with 5,001-10,000 employees
Real User
Top 10
Apr 16, 2026
Monitoring file transfers has become detailed and reporting now provides flexible, time-based insights
Pros and Cons
  • "Splunk Enterprise Security has the capability to pull the report from anytime or any respective time, or if I need it from all the time, then it can be helpful."
  • "Because we are using a licensed DataDog, which gives us more reliable results. And for file logs, we are using a BAM, a business audit and monitoring tool, which gives us a more visualized experience than Splunk Enterprise Security."

What is our primary use case?

Currently we are using Splunk Enterprise Security for monitoring the jobs and along with Splunk Enterprise Security, we are using DataDog where it will be used for monitoring the servers and our URLs.

Currently, we are using it only for monitoring because that is going to be decommissioned very soon. So we have only had it active for monitoring for the last four years.

Currently, we are using the on-premises and we are slowly going to be migrated to the cloud, and then we can use that for whatever we have existing. We can utilize it in the cloud.

Splunk Enterprise Security is only used for our MFT tool purpose, which is integrated with our MFT tool.

What is most valuable?

Splunk Enterprise Security has the capability to pull the report from anytime or any respective time, or if I need it from all the time, then it can be helpful. And we can also set the monitoring for a particular server, particular file type, or a particular user. Those are some of the good features which I really appreciate.

Threat detection is not something we use. Our TechSec team uses their own respective tools such as Qualys to pull out the reports. And apart from that, they mainly look into DataDog.

DataDog will give a more pictorial idea of what went wrong, where it lagged, and where the issue is. But Splunk Enterprise Security won't give that much pictorial detail.

Compared to other tools, Splunk Enterprise Security is kind of user-friendly.

Initially, it was helping us to give the logs and integrate with Splunk Enterprise Security and all.

What needs improvement?

The main challenge is that it runs on the Linux part. So that is a very big challenge for us where we have installed it on the Linux machine. And getting it moved out from the Linux machine is the biggest challenge for us currently. So it is not so friendly for us to do that. That is why we came up with DataDog and then Splunk Enterprise Security is going out.

Now, we currently have completed all the setups. We are currently using it on-premises, but going forward, we will be utilizing the cloud environment.

Because we are using a licensed DataDog, which gives us more reliable results. And for file logs, we are using a BAM, a business audit and monitoring tool, which gives us a more visualized experience than Splunk Enterprise Security.

For how long have I used the solution?

For five years.
Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,924 professionals have used our research since 2012.

What do I think about the stability of the solution?

Currently, there are no stability issues. I am not that good at providing any advice, but these are my few feedbacks.

What do I think about the scalability of the solution?

Currently, there are no scalability issues.

How are customer service and support?

Currently, customer service is limited.

Which solution did I use previously and why did I switch?

We are using a licensed DataDog, which gives us more reliable results.

How was the initial setup?

It is not a support kind of thing. It is just helpful for looking around the logs.

What about the implementation team?

Initially, it was helping us to give the logs and integrate with Splunk Enterprise Security and all.

Which other solutions did I evaluate?

Our TechSec team mostly uses DataDog.

What other advice do I have?

I am using a Globalscape, not Axway.

I am working on MFT and SSIS.

Splunk Enterprise Security is only used for our MFT tool purpose, which is integrated with our MFT tool. Otherwise, our TechSec team mostly uses DataDog.

The complete Splunk Enterprise Security itself is going out, going to be decommissioned. So we are not at all using it. So I do not think there will be any more advancement on that part.

Currently, we do not have it.

I do not have any details about that.

It has had some of it, but as we are moving out of it, we never look into it so deeply. For the time being, it will be just refixed.

It is a good product. I rate this product an overall 8 out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Apr 16, 2026
Flag as inappropriate
PeerSpot user
Manager cybersecurity at Hexion Inc.
Real User
Top 5
Aug 4, 2025
Effectively monitors cybersecurity risks and improves IT landscape visibility
Pros and Cons
  • "From a visibility perspective, the solution has significantly improved our organization by providing a single platform to visualize our entire IT landscape."
  • "The best features I've experienced over the past six years with Splunk Enterprise Security are the ability to create use cases and the flexibility to customize searches and use cases based on our specific requirements."
  • "Regarding room for improvement, I expect Splunk to provide information about new features on a regular basis, such as notifications about enhancements that may improve security posture."

What is our primary use case?

We use Splunk Enterprise Security for security monitoring purposes, and we have many security use cases configured to detect cybersecurity-related risks. We have 100+ use cases related to brute force attacks, ransomware, credential access attacks, et cetera.

We use it for the extra security layer since we want to be very proactive and monitor our infrastructure fully end-to-end.

How has it helped my organization?

We now have a single platform where we can visualize our entire landscape. It's improved our security posture. We can see all the logs getting ingested, and if there are any anomalies, we're able to visualize that as well. The alerts help us be very proactive. We used to miss a few things happening in our organization. Now we get alerts on time. 

What is most valuable?

The best features I've experienced over the past six years with Splunk Enterprise Security are the ability to create use cases and the flexibility to customize searches and use cases based on our specific requirements. 

It's user-friendly. You don't need to be an expert to create a use case. Even a basic understanding will allow you to do the work. There are lots of knowledge articles as well. 

From a visibility perspective, the solution has significantly improved our organization by providing a single platform to visualize our entire IT landscape. This has also enhanced our security posture by enabling us to view all logs.

We do connect with a Splunk representative on a monthly basis. They can proactively provide us with solutions. 

What needs improvement?

Regarding room for improvement, I expect Splunk to provide information about new features on a regular basis, such as notifications about enhancements that may improve security posture. I want these notifications to come to us quite regularly, as we always want to improve our security posture. 

I'm interested in the notifications and alerts aspect, particularly since Splunk Enterprise Security's Mission Control feature was very proactive when it was rolled out.

For how long have I used the solution?

I have been using Splunk Enterprise Security for the last six years.

What do I think about the stability of the solution?

I would rate the stability at eight out of ten; we never had any gap in monitoring. That said, there were instances of backend issues that did not impact our monitoring.

What do I think about the scalability of the solution?

It is a scalable solution for our business, and I would rate it nine out of ten, as we have recently scaled it to monitor operational use cases.

How are customer service and support?

I would rate the technical support as nine out of ten. They are always on top of resolving issues, providing technical account manager details for further assistance. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We had tried IBM QRadar and Azure Sentinel previously.

How was the initial setup?

If I need to set up Splunk from scratch, I don't have to do a lot of planning. It's pretty straightforward. 

It took about a month to deploy Splunk Enterprise Security, as we took many days to plan how to set up the architecture.

There is some maintenance required once it is set up.

What about the implementation team?

The IT team exclusively uses Splunk Enterprise Security for assistance. The team is always there to assist.

What's my experience with pricing, setup cost, and licensing?

I don't deal with pricing. I have a fair understanding based on the market research; from what I've witnessed, the pricing is competitive.

What other advice do I have?

I rate Splunk Enterprise Security higher due to its user-friendliness. That is something on top of my list. 

Splunk Enterprise Security is on top in terms of how users or administrators can manage it. Everything else looks pretty fine regarding the support we get from Splunk Enterprise Security. 

I would rate Splunk Enterprise Security overall as eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
PeerSpot user
Buyer's Guide
Splunk Enterprise Security
August 2026
Learn what your peers think about Splunk Enterprise Security. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,924 professionals have used our research since 2012.
Hamada Elewa - PeerSpot reviewer
System Engineer - Security Presales at Raya Integration
Real User
Top 5
Feb 10, 2025
Achieve comprehensive data visibility with versatile language
Pros and Cons
  • "Splunk Enterprise Security's most valuable features are its stability and the robust Splunk Search Processing Language, allowing extensive customization and analysis capabilities."
  • "Splunk simplifies real-time problem identification and resolution by seamlessly integrating existing customer and vendor systems."
  • "Splunk could enhance its offerings by incorporating modules for network detection and response and fraud management, along with improving its threat intelligence management capabilities."

What is our primary use case?

After the acquisition by Cisco, we are focusing on our partnership with them as a Gold Partner and Tier One reseller. Following the acquisition, we also shifted our focus to Splunk. I am a system integrator implementing Splunk for customers in their environments.

How has it helped my organization?

Splunk has a vast integration with multiple vendors, which makes it easy for our customers to integrate various cloud environments. 

Splunk provides complete visibility when integrated with all installed appliances and applications.

The threat intelligence management feature is a good add-on for startups, especially given its affordability.

Splunk allows organizations to ingest and normalize data effectively.

Splunk simplifies real-time problem identification and resolution by seamlessly integrating existing customer and vendor systems. Its customizable dashboards can be tailored to map and reflect specific environmental needs precisely.

The threat topology and MITRE ATT&CK framework features can help discover the full scope of a security incident, provided they are fully integrated into the customer's environment.

Splunk's comprehensive log visibility enables efficient investigation of malicious activities and breaches. By generating a dashboard that collects logs from firewalls, emails, proxy endpoints, and threat intelligence, Splunk can provide access to critical information within seconds, significantly reducing investigation time compared to other vendors or solutions. This streamlined process, facilitated by Splunk's ability to gather and analyze diverse log data, ensures swift identification and resolution of security incidents.

It helps our customers improve their organization's business resilience.

The unified platform helps consolidate networking infrastructure and security. This single-platform approach offers the advantage of combining multiple technologies and features, streamlining operations and enhancing efficiency.

Implementing Splunk with SOAR capabilities, along with machine learning and AI for alert filtering, can significantly reduce alert volume without constantly interrupting administrators. This streamlined approach ensures that only alerts requiring approval are sent to administrators, optimizing their workflow and efficiency.

The analysts using Splunk, even the free edition, are very satisfied with the information it provides for their investigations.

Splunk has helped customers accelerate their security investigations by integrating AI and machine learning into its platform. This integration automates many basic tasks and saves valuable time.

Splunk helps reduce our customer's mean time to resolve. 

What is most valuable?

Splunk Enterprise Security's most valuable features are its stability and the robust Splunk Search Processing Language, allowing extensive customization and analysis capabilities.

What needs improvement?

Splunk could enhance its offerings by incorporating modules for network detection and response and fraud management, along with improving its threat intelligence management capabilities. Additionally, the pricing could be made more competitive.

For how long have I used the solution?

I have been using Splunk Enterprise Security for almost six months.

What do I think about the stability of the solution?

Splunk is a very stable platform.

What was our ROI?

My customers feel it's a good investment, but Splunk updated its price models recently.

What's my experience with pricing, setup cost, and licensing?

One of Splunk's two major disadvantages is its high cost. The platform requires significant financial investment and resources, making it expensive despite its comprehensive features.

What other advice do I have?

Splunk has disadvantages such as cost and resource requirements. However, once I invest, it's a powerful platform that ranks number one in SIEM and observability. I rate the product nine out of ten due to pricing concerns and threat intelligence management not being advanced.

I believe Splunk is the top SIEM tool. However, the term "enterprise security" is misused when applied to Splunk. While many vendors claim to offer "enterprise security," true enterprise security should cover all aspects of cybersecurity. Splunk excels in SIEM, SOAR, and UEBA, but it doesn't address other crucial areas like firewalls, PAM, or web/mail gateways. Therefore, Splunk shouldn't be categorized as an "enterprise security" solution. Although Splunk leads in SIEM with its superior visibility and observability, it lacks presence in other essential cybersecurity domains.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer2898978 - PeerSpot reviewer
Splunk Architect at a tech consulting company with 11-50 employees
Real User
Top 20
Sep 15, 2026
Analyst workflows have improved and investigations gain speed with integrated automation
Pros and Cons
  • "Analyst productivity has risen because they started using Splunk instead of the other product, the third-party SIEMs, and the detection has really improved because they are doing everything by SLA and fitting into these tight schedules, and our clients really love Splunk Enterprise Security."

    What is our primary use case?

    My main use case for Splunk Enterprise Security involves security and analyzing things using Splunk Enterprise in a SOC, and also building searches and findings there for our clients.

    We utilized Splunk Enterprise Security for building new findings, and those findings are being analyzed right now by our clients, our bank client analysts, who are doing their best with Splunk Enterprise Security.

    I cannot share anything unique about my main use case because I am under NDA, but we are trying to implement new products from Splunk, such as adding Splunk SOAR to Splunk Enterprise Security environment. We came to this conference to learn the best ways to implement it and to take experiences from other people who might share it with us.

    What is most valuable?

    The best features Splunk Enterprise Security offers are findings, investigations, and the actions inside of Splunk Enterprise Security, as well as the audit for upper management to see how the analysts are working. Additionally, there is a very convenient way of integrating Splunk with SOAR, not just Splunk SOAR but even other SOARs, and that is why we think Splunk Enterprise Security is the best in its field.

    The convenient way of integrating Splunk SOAR with Splunk Enterprise Security is that our analysts and our L2s can run playbooks easily just from Splunk Enterprise Security without entering Splunk SOAR. They can do everything from one window without jumping from Splunk Enterprise Security to Splunk SOAR, and everything can be run from the investigation tab. That is what is great about that feature.

    Concerning the audit capabilities of Splunk Enterprise Security, clients sometimes ask for compliance or audit of their whole SOC team, and that is how the audit feature of Splunk Enterprise Security is usually used.

    Because we are a Splunk partner and also resellers of Splunk, it has impacted us in many ways, but mostly we are getting many clients because Splunk is great at presenting it to someone. We are also getting really good deals when selling it to our clients from Splunk itself, which means the good deals come from Splunk.

    Analyst productivity has risen because they started using Splunk instead of the other product, the third-party SIEMs. The detection has really improved because they are doing everything by SLA and fitting into these tight schedules. Our clients really love Splunk Enterprise Security.

    Splunk Enterprise Security has helped our clients detect threats faster, and I estimate by approximately fifty percent.

    What needs improvement?

    To improve Splunk Enterprise Security, I suggest starting to add SOAR inside of Splunk Enterprise Security without having two separate servers for that. I believe it might be accomplished in the future.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for five years.

    What do I think about the scalability of the solution?

    Splunk Enterprise Security's scalability is great.

    How are customer service and support?

    The customer support for Splunk Enterprise Security is good.

    Which solution did I use previously and why did I switch?

    We did not previously use a different solution.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is that it was light work and light price.

    What other advice do I have?

    My advice for others looking into using Splunk Enterprise Security is to just buy it. I would rate this review a ten out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner, Reseller
    Last updated: Sep 15, 2026
    Flag as inappropriate
    PeerSpot user
    Information Security Architect at UMMS
    Real User
    Top 5
    May 29, 2025
    Incident reviews and machine learning capabilities help identify and prevent incidents
    Pros and Cons
    • "The incident review in Splunk Enterprise Security seems to be the most helpful feature."
    • "Splunk Enterprise Security is more advanced compared to other solutions, which makes it stand out as a better option."
    • "It would be nice to have more advanced UEBA in Splunk Enterprise Security. Additionally, it would be beneficial if they offered more threat intel feeds for free."
    • "One thing that I probably dislike the most about the Splunk product is their support."

    What is our primary use case?

    We use Splunk Enterprise Security for security monitoring.

    How has it helped my organization?

    Advanced correlation capabilities help to identify the patterns of malicious activities.

    Machine learning capabilities in Splunk Enterprise Security have been effective for identifying and preventing incidents. Through machine learning, they correlate all the data and create notable events, which helps us identify malicious or suspicious traffic.

    We have used the risk-based alerting a little bit. So far, it's been just fine. We haven't gone deep into it. Our other operations team hasn't utilized it to its full capacity, but it makes a pretty good filter overall.

    The impact of automated responses provided by Splunk Enterprise Security has been very good on the efficiency of routine security operations.

    What is most valuable?

    The incident review in Splunk Enterprise Security seems to be the most helpful feature. 

    What needs improvement?

    It would be nice to have more advanced UEBA in Splunk Enterprise Security. Additionally, it would be beneficial if they offered more threat intel feeds for free. 

    Furthermore, incorporating Attack Analyzer into the main product instead of having it as a separate paid purchase would be an improvement.

    For how long have I used the solution?

    I have been using the solution for about three years.

    What do I think about the stability of the solution?

    I've had an issue only once with one of their products, but overall, it's been pretty good.

    What do I think about the scalability of the solution?

    Its scalability is pretty good.

    How are customer service and support?

    For Splunk Enterprise Security, it's been pretty good. For the regular Splunk Enterprise Platform, overall, it's like a C-minus. One thing that I probably dislike the most about the Splunk product is their support.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    I previously used LogRhythm. Splunk Enterprise Security is more advanced compared to other solutions, which makes it stand out as a better option.

    How was the initial setup?

    I deployed Splunk Enterprise Security using professional services, and overall, it was good. My main responsibility was handling the coordination. The full implementation took about four months.

    Approximately 90% of maintenance is done by Splunk.

    What about the implementation team?

    The implementation was handled by myself.

    We purchased Splunk Enterprise Security through a reseller called AccessIT.

    What's my experience with pricing, setup cost, and licensing?

    Splunk Enterprise Security is a bit expensive overall, but it provides good value.

    What other advice do I have?

    I would rate this solution an eight out of ten overall.

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    reviewer2900013 - PeerSpot reviewer
    Developer at a tech vendor with 10,001+ employees
    Real User
    Top 20
    Sep 17, 2026
    Detection workflows have improved and now provide faster, context-rich threat response
    Pros and Cons
    • "Splunk Enterprise Security has positively impacted my organization by providing one pane of glass for analysts to triage and respond to alerts."
    • "I think Splunk Enterprise Security can be improved by providing more out-of-the-box contextual information for alert triage, investigation, and response."

    What is our primary use case?

    My main use case for Splunk Enterprise Security is detection engineering and detection and response.

    A specific example of how I use Splunk Enterprise Security for detection engineering or response is detecting potential account compromise, DLP, and insider risk.

    Splunk Enterprise Security helps me detect those issues by enabling us to develop detection content based on threat intelligence research, and then we use the frameworks available to us in Splunk Enterprise Security to enrich those detections to provide analysts with contextual information to help them triage and respond to the alert.

    What is most valuable?

    The best features Splunk Enterprise Security offers are assets and identity enrichment and one pane of glass view.

    Splunk Enterprise Security has positively impacted my organization by providing one pane of glass for analysts to triage and respond to alerts.

    The single pane of glass has changed my team's workflow by reducing mean time to detect and respond and providing actionable insights into improving our security posture.

    Splunk Enterprise Security has helped improve my organization's business resilience by helping us identify threats quicker and triage and respond faster.

    It has helped reduce my team's average mean time to resolve (MTTR) metric, although I do not have the exact numbers.

    What needs improvement?

    I think Splunk Enterprise Security can be improved by providing more out-of-the-box contextual information for alert triage, investigation, and response.

    Regarding Splunk Enterprise Security's AI capabilities, the accuracy and reliability of output have room for improvement.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for about 10 years.

    What do I think about the stability of the solution?

    Splunk Enterprise Security is stable.

    What do I think about the scalability of the solution?

    Splunk Enterprise Security's scalability is sufficient.

    How are customer service and support?

    Splunk Enterprise Security's customer support is good.

    What other advice do I have?

    Splunk Enterprise Security's risk-based alerting (RBA) has impacted our alert volume and analyst productivity by allowing us to send low fidelity notables to the risk index so we can still maintain a record of that and focus on curating correlation searches to as high fidelity as possible.

    I have found the threat topology and MITRE ATT&CK framework features in Splunk Enterprise Security helpful for understanding the full scope of a security incident, as we do map our content to MITRE, and the features available in Detection Studio with MITRE Attack coverage offer us an opportunity to improve in that space by closing some gaps identified.

    We are not leveraging threat intelligence, but I think the features in Detection Studio offer more areas where we could look for insights into how to close the MITRE Attack coverage gaps we have.

    My advice for others looking into using Splunk Enterprise Security is that before looking at Splunk Enterprise Security, organizations must evaluate what their use case and priority use cases are and evaluate the best approaches available so they know what data to load into Splunk Enterprise Security and what detections to develop against that data.

    I would rate this product an 8.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 17, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2900007 - PeerSpot reviewer
    Cybersecurity Analyst at a energy/utilities company with 501-1,000 employees
    Real User
    Top 20
    Sep 16, 2026
    Centralized security logs have improved detections and reduced analyst fatigue
    Pros and Cons
    • "Splunk Enterprise Security Essentials has contributed to a reduction in analyst burnout or fatigue, and the speed of finding data and correlating it is a big helper in improving my daily work experience and retention for our security team."
    • "I still think we're in a significant process of getting the use cases and utilization of Splunk sorted out."

    What is our primary use case?

    My main use case for Splunk Enterprise Security is using the SIEM for detections. A quick specific example of what kind of detections I use Splunk Enterprise Security for includes mostly the built-in ones, with one that comes to mind being possible travel.

    What is most valuable?

    I really appreciate the new Detection Studio feature in Splunk Enterprise Security as it helps me look at detections and figure out if they're right for our environment.

    Splunk Enterprise Security has positively impacted my organization by helping to centralize all our security logs and quickly investigate IT firewall logs and security logs, keeping everything in one place that I can easily search.

    Having everything centralized has really improved the workflow of looking through logs. When I'm investigating an incident, I can look through it more quickly to decide and investigate.

    The accuracy and reliability of the AI output in Splunk Enterprise Security have been really good for me so far. I've had to adjust it a little to ensure it's using the correct indexes, but other than that, it's been really helpful for writing SPL and guiding me on searches.

    What needs improvement?

    I think more integration with the AI agent could make my experience better.

    For how long have I used the solution?

    I have been using Splunk Enterprise Security for nine months.

    What do I think about the stability of the solution?

    Splunk Enterprise Security is stable and works properly.

    What do I think about the scalability of the solution?

    The scalability has been good, as it has been scaling well with new detections and more ingests.

    How are customer service and support?

    I haven't had to deal with any customer support for Splunk Enterprise Security, but when issues arise with certain apps, my rep quickly connects me with an expert, and they help very well.

    Which solution did I use previously and why did I switch?

    For our SIEM, we previously used Sentinel. We decided to switch to Splunk Enterprise Security because we wanted to move and use Splunk as a data analyst tool to send all our data to it.

    What was our ROI?

    I still think we're in a significant process of getting the use cases and utilization of Splunk sorted out. We are starting to see the value in being able to correlate data and save time in that sense, but I believe we can definitely utilize Splunk more.

    What other advice do I have?

    I find the threat topology and MITRE ATT&CK framework features helpful for discovering the overall scope of an incident, as they provide a good overview of what MITRE attacks we cover and which ones we're missing, giving us a good idea of what detections or new data we need to ingest.

    Splunk Enterprise Security has helped me detect threats faster. With the risk-based alerting, it's easier to detect things and respond to incidents.

    Splunk Enterprise Security Essentials has contributed to a reduction in analyst burnout or fatigue. The speed of finding data and correlating it is a big helper in improving my daily work experience and retention for our security team.

    I don't think we have been really using the integration of threat intelligence directly into the TDIR workflow yet, so I can't say much about how it has changed my approach to proactive defense.

    Since we don't have Enterprise Security Premium and just have the base version, we don't have SOAR and UEBA, which means the consolidation of them into a single interface has not improved my team's operational efficiency.

    My advice for others looking into using Splunk Enterprise Security is to study and understand the Splunk fundamentals, as that will help you understand what Splunk Enterprise Security is doing with your data and how it serves as an add-on on top of Splunk to fully utilize it. I would rate my overall experience with Splunk Enterprise Security an 8 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Sep 16, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2869248 - PeerSpot reviewer
    Solutions Architect at a tech vendor with 1-10 employees
    Reseller
    Top 20
    Jul 15, 2026
    Unified monitoring has improved hybrid log visibility but pricing and compliance need refinement
    Pros and Cons
    • "The advantages of Splunk over its competitors include the unified platform which includes everything from security to logging."
    • "There are sometimes issues with availability where you have to wait a bit longer."

    What is our primary use case?

    I have conducted research for some of our clients since I work in a consultancy firm, and customers sometimes have specific products. I made research on customer preference which usually leads them to go with Splunk.

    We usually deal with Splunk for log management as a SIEM solution, where customers have logs on-premises and on the cloud and want to have a consolidated view. We recommend Splunk in these scenarios.

    I am not very much aware of Splunk Enterprise Security; I research this and put it in my proposals mostly for log management.

    Some of our customers are using the product.

    I would generally recommend Splunk Enterprise Security for companies which are highly regulated or have to mandate certain compliances.

    I would generally recommend it for bigger companies, not for smaller or mid-sized ones.

    There are sometimes issues with availability where you have to wait a bit longer.

    We deal with Splunk Essentials for certain customers, especially banks, who only need a SIEM solution.

    What is most valuable?

    The advantages of Splunk over its competitors include the unified platform which includes everything from security to logging. The real advantage is that they can deploy Splunk Cloud and have availability in the UAE region, especially because we deal with this within GCC and UAE mostly. Another advantage of Splunk Observability Stack is that you can deploy this solution on-premises completely, which is the product advantage I see.

    It contributes to a reduction in analyst burnout or fatigue in our company because compliance mandates having a SIEM solution. Other than managing the logs on CloudWatch or using native tools or other tools, this platform has an edge by allowing you to query logs effectively, reducing the time to recover or find logs.

    Splunk Enterprise Security has improved visibility across hybrid or multi-cloud environments, and they keep on improving their product, making it good for hybrid cloud as they have their on-premises stack and the cloud.

    The consolidation of SIEM, SOAR, and UEBA into a single interface has improved our customers' operational efficiency as it allows correlation of logs, SIEM, and UEBA, thus enhancing customers' efficiency and reliance on the product while reducing the time to diagnose issues.

    What needs improvement?

    In terms of weaknesses and room for improvement, I do not see certain weaknesses, but it can get really tricky in terms of pricing if the log volumes are very high, as it can get costly, which is the only uncertain aspect I believe regarding this tool.

    They should change the licensing model and make the pricing estimations more accurate to better account for logging and make the pricing a bit lower, especially for logs and analytics.

    To make it closer to a perfect score, they could add more features related to security posture management and add certain compliances like GDPR and other regional-specific compliances to ensure that you comply with those and have that score built in. Although they have certain features, this can be further improved.

    For how long have I used the solution?

    I have been using this solution for six months.

    How are customer service and support?

    The technical support is good. If you have Enterprise support, their team understands the platform well, and I would rate them a seven, though sometimes there are issues with availability. Because of the issues of availability, sometimes you have to wait a bit longer.

    What other advice do I have?

    From the deployment perspective, it is not very difficult to deploy and integrate Splunk. They have good resources, and we usually deploy this on AWS without many challenges, as it deploys really well with pre-built stacks that you can use connectors with. We usually prefer the AWS Marketplace for purchasing. I would rate this product a seven overall.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
    Last updated: Jul 15, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2755854 - PeerSpot reviewer
    Senior Cyber Architect at a tech vendor with 10,001+ employees
    Real User
    Top 10
    Sep 11, 2025
    Improves threat detection through integrations and provides valuable support for meeting compliance objectives
    Pros and Cons
    • "I appreciate the integrations with the SOAR architectures and the expandability that can be used throughout the entire ecosystem of Splunk Enterprise Security."
    • "The system can be intimidating, and sometimes the concepts conveyed in the documentation require adjustment."

    What is our primary use case?

    My main use case for Splunk Enterprise Security is getting observability and insights in order to meet compliance objectives.

    What is most valuable?

    I appreciate the integrations with the SOAR architectures and the expandability that can be used throughout the entire ecosystem of Splunk Enterprise Security. They've improved my threat detection capabilities.

    What needs improvement?

    The system can be intimidating, and sometimes the concepts conveyed in the documentation require adjustment. The product is mature and continuing to mature. There could be a better opportunity to let larger groups outside of the community know about the ease of deploying the product.

    I'm finding that newer generations, including my own, don't respond well to TL; DRs that often come from third parties and are often incorrect. If there was more of a quick answer, perhaps with Splunk AI, they could start implementing that on the documentation page to let people who have trust in that get a quicker answer.

    For how long have I used the solution?

    Professionally, I have been using Splunk Enterprise Security in the last one to two years. Personally, I've used it several times as a hobby product and competitively in cyber games.

    What do I think about the stability of the solution?

    The product is mature. 

    How are customer service and support?

    I don't directly deal with technical support.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Prior to adopting Splunk Enterprise Security, I was using another solution to address similar needs, however, I can't go into details.

    How was the initial setup?

    I would describe my experience with deploying Splunk Enterprise Security as one that needs some more hand-holding. Some aspects of the language and understanding can be challenging for individuals unfamiliar with Splunk. There are opportunities to improve that dissemination.

    With training, I find deployment relatively easy. There's some self-service that has to be done as a user in terms of learning and understanding the product. Once you understand those workflows, it presents as a relatively easy and intuitive product to expand and grow into.

    What was our ROI?

    I have seen a return on investment with Splunk Enterprise Security. It's a useful system, and I would highly advocate it with any Splunk deployment.

    What's my experience with pricing, setup cost, and licensing?

    I'm not involved on the licensing side. 

    What other advice do I have?

    The features that have been demoed and debuted in Splunk Enterprise Security are of particular interest, and I'm interested to see where that journey continues. I find the process for customizing, developing, testing, deploying, and refining detections in Splunk Enterprise Security relatively easy with training.

    My advice to other organizations considering Splunk Enterprise Security is to try it. I would suggest getting a demo from Splunk as that's the worthwhile approach. It's better to see all the powers that this tool can bring in terms of those capacities rather than trying to figure it out on your own journey.

    I would rate Splunk Enterprise Security an eight out of ten. The only reason for this rating is, from an outside-in perspective, as someone who hasn't spent time either deploying it themselves or learning more of the nuances of how clustered designs work, it can be an intimidating experience and requires a lot of hand-holding. This creates a barrier to adoption.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Vice President Research And Development at OSINT Ambition
    Real User
    Top 20
    Jul 30, 2025
    Helps us manage logs easily and detect threats effectively
    Pros and Cons
    • "Splunk Enterprise Security performs 80% of our work on its own; we just have to do the remaining 20%, which gives us the freedom to explore and detect threats more effectively."
    • "Its deployment is difficult. I remember when I first started learning, I faced several challenges, especially when deploying VMware in a virtual environment."

    What is our primary use case?

    I work in a SOC team where I study threat hunting and threat determination. Most of my work is based on looking for malware traffic or suspicious traffic in Splunk Enterprise Security. I belong to the SOC team.

    What is most valuable?

    The best feature about Splunk Enterprise Security is its clean interface and the detail it provides. It helps us manage logs with a very clean interface, which is not available in other software. 

    They also provide extensive learning resources on their official site that help us while performing tasks. Its documentation and community are very strong, making it a perfect SOC tool. If we come across any problem, we can search the community or consult the documentation for solutions. 

    It is very clean and detailed, helping us detect threats easily. Splunk Enterprise Security performs 80% of our work on its own; we just have to do the remaining 20%, which gives us the freedom to explore and detect threats more effectively.

    What needs improvement?

    The machine learning capabilities of Splunk Enterprise Security are good, but they can be improved. In a changing threat landscape, its machine learning capability can be improved in behavior-based analysis because signature-based analysis does not work very well currently.

    It can improve in detecting new types of attacks or IOCs through behavior-based learning capabilities. For example, if there are malware traffics incoming, it should detect them using network logs more precisely, as most malware traffic uses the same kind of port or attack.

    There should be a community program or hackathon-type events where people can develop more advanced and sophisticated machine learning models for Splunk Enterprise Security to enhance its functionality. 

    Adding a chatbot similar to GitHub Copilot in Splunk Enterprise Security would be beneficial. It would help write different kinds of sophisticated queries and assist in solving problems we encounter, similar to what we have in VS Code.

    There is good scope for developing Splunk Enterprise Security for low-level systems such as Raspberry Pi. However, for server deployment, a robust server is essential. Development should focus on making Splunk Enterprise Security capable of running on devices such as Raspberry Pi.

    For how long have I used the solution?

    I used Splunk Enterprise for a long time in previous organizations. I have also used the Community version for my personal projects, which is available for free. I have experience with both Splunk Enterprise Security and the normal Splunk Community version. I still use Splunk Enterprise Security quite frequently when working with SOC and related processes.

    What do I think about the scalability of the solution?

    Splunk Enterprise Security is highly scalable, which is why approximately 95% of the industry uses it without experiencing scalability problems. It performs exceptionally well when discussing scalability.

    How are customer service and support?

    I do not remember contacting technical or customer support. Whenever I faced any problem, I usually consulted the documentation or community, and 99% of my problems were solved that way.

    Which solution did I use previously and why did I switch?

    I have used Wazuh, Elasticsearch, Kibana, and some basic Linux SOC management tools such as Zeek and Wireshark as alternatives to Splunk Enterprise Security. However, I find Splunk Enterprise Security to be much more advanced than those tools, as they lack automation and machine learning capabilities, requiring customization from the user. Splunk Enterprise Security is more refined and offers a better experience.

    How was the initial setup?

    Its deployment is difficult. I remember when I first started learning, I faced several challenges, especially when deploying VMware in a virtual environment. It was quite a difficult task. However, when deploying on a server, I would consider it to be at a medium level of difficulty. On the other hand, if you're deploying for a learning lab or something similar, it’s pretty much on the hard side.

    For personal home labs, it is a one-person job, meaning a seasoned professional can handle it. For enterprise-level deployment, a person managing operations and a person handling server management is sufficient. After the initial deployment, one person is enough for a mid to low-level company, while a higher-order company requires a team to operate Splunk Enterprise Security.

    Splunk Enterprise Security requires very little maintenance on my end, as it has improved significantly. If there are no frequent changes in the server, there is not much maintenance required. I have not invested much time in updates or maintenance, so once deployed, you just need a good professional to use it; maintenance is not much of a concern.

    What's my experience with pricing, setup cost, and licensing?

    The pricing of Splunk Enterprise Security is fair for what it provides. If someone wants everything for free, it is not a reasonable expectation. Everything comes at a price, and I find it to be affordable, which is why every industry uses it. Its pricing is fair, and the community version works well for learning purposes.

    What other advice do I have?

    I would rate Splunk Enterprise Security an eight out of ten.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.
    Updated: August 2026
    Buyer's Guide
    Download our free Splunk Enterprise Security Report and get advice and tips from experienced pros sharing their opinions.